CVE-2021-21339 Information

Description

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57 7.6.51 8.7.40 9.5.25 10.4.14 11.1.1 user session identifiers were stored in cleartext - without processing of additional cryptographic hashing algorithms. This vulnerability cannot be exploited directly and occurs in combination with a chained attack - like for instance SQL injection in any other component of the system. This is fixed in versions 6.2.57 7.6.51 8.7.40 9.5.25 10.4.14 11.1.1.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Reference

https://packagist.org/packages/typo3/cms-core https://typo3.org/security/advisory/typo3-core-sa-2021-006 https://github.com/TYPO3/TYPO3.CMS/security/advisories/GHSA-qx3w-4864-94ch

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

NONE

Base Severity

7.5

Share on: